Tom Rolvers's Avatar

Tom Rolvers

@azurewithtom.bsky.social

Love Microsoft Security, love to ride his Canyon roadbike, happy dad. ๐Ÿ“‚ GitHub: https://github.com/awt-tom ๐Ÿ’ผ LinkedIn: https://linkedin.com/in/tomrolvers โœ๏ธ Blog: https://AzurewithTom.com Working @ https://yellowarrow.nl

46 Followers  |  53 Following  |  15 Posts  |  Joined: 04.12.2024  |  1.8539

Latest posts by azurewithtom.bsky.social on Bluesky

Preview
MSRC Case: When Temporary Global Admin Rights Donโ€™t Expire in Microsoft Entra PIM A confirmed and fixed Microsoft Entra PIM flaw reported to MSRC - learn what happened, how it was fixed, and what admins should check.

Ever seen PIM throw โ€˜CannotDeleteLastAdminAssignmentโ€™?

๐ŸงฉI ran into a strange edge case that ended up as an MSRC report, Microsoft confirmed and fixed it.

Full write-up ๐Ÿ‘‡
๐Ÿ”— azurewithtom.com/posts/MSRC-C...

#MVPBuzz

12.10.2025 23:44 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Windows Autopatch Client Broker: What It Is, When to Use It, and Why It Matters In this post, weโ€™ll break down what it does, when you need it, and how to align it with your organizationโ€™s update strategy.

Reminder for #WindowsAutopatch admins:
Migrate to the Win32 Client Broker for better reliability and on-demand deployment. Script-based installs still work, but the Win32 app is the new standard.
โžก๏ธ azurewithtom.com/posts/Manage...

08.10.2025 20:41 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Windows Autopatch Client Broker: What It Is, When to Use It, and Why It Matters In this post, weโ€™ll break down what it does, when you need it, and how to align it with your organizationโ€™s update strategy.

๐Ÿš€ New blog post: Windows Autopatch Client Broker โ€“ What It Is and Why It Matters

After sharing the new Autopatch capabilities, I got a lot of questions about the Client Broker.
Good news: itโ€™s getting an update!

Read here ๐Ÿ‘‰ azurewithtom.com/posts/Manage...

#Microsoftsecurity #Intune #MVPBuzz

27.08.2025 14:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Say Goodbye to Basic Authentication in Exchange Online: What You Need to Know Prepare for the deprecation of Basic Authentication in Exchange Online by September 2025. Start detect legacy sign-ins (including ROPC) using Microsoft Entra ID, disabling Basic Auth in Microsoft 365,...

๐Ÿšจ Call to action ๐Ÿšจ

Starting September 2025, Microsoft will permanently disable Basic Authentication for SMTP AUTH.

I just published a new blog post about this:
azurewithtom.com/posts/Say-go...

#Microsoft365 #ExchangeOnline #MicrosoftEntra

10.06.2025 22:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Whats New in Windows Autopatch Learn how Windows Autopatch lets you orchestrate updates for Windows, Microsoft 365 Apps, Microsoft Edge, and Teams. All from a single automated solution. Discover whatโ€™s new in 2025, including hotpat...

Windows Autopatch just got better in 2025:
โœ… Hotpatching for Win11
โœ… Better reporting in Intune
โœ… Now for Business Premium

azurewithtom.com/posts/Whats-...

I wrote a quick rundown on whatโ€™s new + how to get started:

#Windows11 #Autopatch #Intune #Hotpatch #MicrosoftSecurity

20.05.2025 11:42 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Implementing Attack Surface Reduction Policies Start implement Microsoftโ€™s Attack Surface Reduction (ASR) policies today!

New blogpost!

Implementing "Attack Surface Reduction" policies is in my opinion mandatory.
If you have not yet touched this feature, please make sure to give it a shot and configure it!

azurewithtom.com/posts/Attack...

#ASRrules #MicrosoftSecurity #AttackSurfaceReduction #Hardening #MDE

14.04.2025 15:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
E5 Security Addon Now Available to Microsoft 365 Business Premium Enhance your Microsoft 365 Business Premium security with the E5 Security Addon. Gain access to advanced Defender features and security hardening tools.

๐Ÿš€ Microsoft 365 Business Premium has a new friend! ๐Ÿ”

You can now add the E5 Security Add-on!

๐Ÿ“ข Important: Check out if your license state is correct!

๐Ÿ”— Read more about it: azurewithtom.com/posts/E5-Sec...

#Entra #E5Security #MDO #MDE #MicrosoftDefender #Microsoft

11.03.2025 20:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The hidden danger of device code phishing Currently there is a peak in abuse of device codes which are gathered by phishing attempts

A small write-up about Device Code abuse.

Microsoft recently revealed an ongoing phishing campaign by Storm-2372, targeting authentication methods that use device codes.
#EntraID #RestrictDeviceCode #ClientID #Microsoft

azurewithtom.com/posts/The-hi...

18.02.2025 20:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿšจ ๐‰๐จ๐ข๐ง ๐ฎ๐ฌ ๐จ๐ง ๐Œ๐š๐ซ๐œ๐ก 6๐ญ๐ก ๐Ÿ๐จ๐ซ #Yellowhat ๐Ÿ‘ท A ๐’ˆ๐’๐’๐’ƒ๐’‚๐’ ๐’๐’Š๐’—๐’†๐’”๐’•๐’“๐’†๐’‚๐’Ž dedicated to Microsoft Security ๐Ÿฅท Ticket sales NOW OPEN for live-audience (๐˜ˆ๐˜ฎ๐˜ด๐˜ต๐˜ฆ๐˜ณ๐˜ฅ๐˜ข๐˜ฎ): yellowhat.live ๐˜Œ๐˜น๐˜ต๐˜ณ๐˜ฆ๐˜ฎ๐˜ฆ๐˜ญ๐˜บ ๐˜ญ๐˜ช๐˜ฎ๐˜ช๐˜ต๐˜ฆ๐˜ฅ ๐˜ฒ๐˜ถ๐˜ข๐˜ฏ๐˜ต๐˜ช๐˜ต๐˜บ!

16.01.2025 11:48 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Optimize your SOC with SIEM and XDR Recommendations Use the Microsoft XDR optimization feature to improve a unified SIEM and XDR environment

New blogpost:

Check out my latest blog post on the new Unified Coverage Management experience in the Microsoft Defender portal.

Sentinel and your XDR unified

azurewithtom.com/posts/Optimi...

#Cybersecurity #MicrosoftSentinel #XDR #Optimization #UnifiedCoverage #MITREATTACK

09.01.2025 13:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Workplace Ninjas Norway 2025: Call for Speakers Join us at Workplace Ninjas Norway 2025ย  where IT experts and community leaders come together to share knowledge, best practices, and the latest advan...

I have submitted my session โ€œBehind the Scenes of Phishing: Understanding and Defending Against AitM Attacksโ€ for speaking at Workplace Ninjas Norway 2025.

Have you submitted a session already? You have until 28 February to submit one yourself!

sessionize.com/workplace-ni...

11.12.2024 19:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Bringing Microsoft Sentinel Workbooks to the Microsoft XDR Portal Microsoft has added the Microsoft Sentinel Workbooks to the XDR portal

๐Ÿš€ You can now access Microsoft Sentinel Workbooks directly in the Microsoft XDR portal!

No more jumping between portals. ๐ŸŽฏ
azurewithtom.com/posts/Bringi...

#Cybersecurity #MicrosoftSentinel #XDR #Workbooks

11.12.2024 12:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Upload your analytic rules to Azure Devops Today we will create our detection rules and make them available in Azure Devops

๐Ÿš€ New Blog Alert: Store your fresh created detection rules in Devops

I will post more of these blogs in the future on how to deploy the rules, use a pipeline and automate validation.

azurewithtom.com/posts/Upload...

Got feedback? Please let me know!

05.12.2024 15:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Should be all set now! โœŠ

04.12.2024 22:47 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Generate ready to use analytic rules We will use a script I recently created to generate a set of analytic rules, ready to be used in Microsoft Sentinel.

Hey @merill.net ๐Ÿ‘‹, I just got in on Bluesky! Am I late to the party?

I also added Bsky to my web blog to share pages. Due to a nice upgrade I am able to deploy blogs easier now. So expect some new ones on here.

Thanks for having me motivated to check this out!

azurewithtom.com/posts/Genera...

04.12.2024 20:50 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@azurewithtom is following 20 prominent accounts